Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
BrazilChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Brazil does not force data to stay inside the country. Personal data can leave, but since August 2025 you normally need a contract written by the regulator, word for word, signed with whoever receives it. Sending data to the European Union needs nothing extra. The regulator is awake and has started switching features off large platforms.
- The catch
- Brazil is often listed as a data-localisation country. It is not one. The old rule that pushed federal government email and data onto Brazilian systems was scrapped in 2018, and today's federal cloud rules do not require Brazilian soil. The real constraints are different in shape: banks must keep the central bank able to reach their data wherever it sits, and since July 2026 digital platforms must have an actual office and a legal representative inside Brazil.
- Does this apply to me?
- Yes. Brazil's privacy law reaches a company with no office in Brazil, as long as it collects data in Brazil or offers goods or services to people here. There is no size or revenue threshold that lets you out. The privacy law itself does not make you appoint anyone local — but two newer rules do, and if you run a digital platform you now need a registered office and a legal representative in Brazil.High confidence
- Can the data leave the country?
- Yes, with paperwork. Brazil has no rule making anyone keep a copy of anything inside the country — not for banks, not for hospitals, not even for the federal government's own cloud. What it has instead is a permission slip: before personal data leaves, you need one of a short list of approved legal grounds. Industry rules add conditions on top, but none of them is a wall.High confidence
- What do I have to do to send it abroad?
- Pick one of five routes. The easy one is the European Union: since January 2026 Brazil treats it as safe, so nothing extra is needed. For everywhere else, the normal route is a set of standard contractual clauses that the regulator itself wrote — you copy them into your contract exactly, and you may not edit them. A deadline to retrofit older contracts already passed, on 23 August 2025.High confidence
- Who enforces this — and are they actually working?
- The National Data Protection Authority, and it is genuinely working. A law passed in February 2026 gave it real independence, 200 new specialist jobs and its own budget. In August 2026 it ordered Discord to switch off live video streaming in Brazil within three working days, to protect children. Banking, telecoms, insurance and securities regulators enforce their own rules in parallel and have done so for years.High confidence
- How long must I keep it, and when must I delete it?
- Both directions, and they pull against each other. The floor: internet access providers must keep connection records for one year, websites and apps must keep access records for six months, and tax records need five years. The ceiling: the privacy law says personal data must be deleted once you have finished doing what you collected it for. Where the two clash, the legal duty to keep wins — the law lists that as an express reason to hold on.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. Privacy: three working days to tell the regulator AND the affected people, once you have confirmed a breach that could really hurt them. Platform content: two hours to take down intimate images shared without consent, once notified. On top of that, banks report incidents to the central bank and telecoms operators report to the telecoms regulator under their own separate timetables.High confidence
- What's the trap?
- Five. (1) Your European standard contract is not automatically good enough — Brazil wrote its own clauses and you must copy them exactly, unedited, and the deadline to fix old contracts passed on 23 August 2025. (2) A child in Brazil is under 12 and an adolescent is 12 to 17, but the social media rule bites at 16 — accounts for anyone up to 16 must be tied to a parent's account, and asking users to state their own age is banned. (3) Since 20 July 2026 a digital platform needs an actual registered office in Brazil, not just a lawyer on retainer. (4) The biggest fine is not in the privacy law: the internet law allows up to 10 percent of your group's Brazilian revenue. (5) The regulator can order your database blocked or your processing suspended, which usually hurts more than any cheque.High confidence
- What's about to change?
- One firm date: January 2027, when the regulator moves from monitoring platforms to full enforcement of the children's digital rules. Brazil's artificial intelligence bill is still only a bill — it was sitting in a committee waiting for a report as recently as June 2026, so do not plan around it. The bigger risk is not new law: it is that the regulator can add or withdraw approved destinations for data transfers by publishing a single resolution, with no consultation.High confidence
- Hardest industry wall
- None found.
United KingdomChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Data can leave the United Kingdom, but you need the right paperwork first. Sending it to Europe or to about fifteen other approved places needs nothing extra. Anywhere else needs a government-published contract and a risk check. No general law forces data to stay in Britain. The privacy regulator is busy and its fines are getting bigger.
- The catch
- The easy headline stops being true in three places. Telecoms operators must keep backup copies of key network information inside the United Kingdom. National Health Service patient records may only be sent to countries the United Kingdom has formally approved, which rules out the standard contract route. And government material classified SECRET or above cannot sit in public cloud at all. Everyone else can store data abroad with the right contract in place.
- Does this apply to me?
- Yes. British privacy law reaches a company anywhere in the world if it deliberately offers goods or services to people in the United Kingdom, or watches what they do online. There is no size or revenue floor to hide under. If you are caught and have no British office, you generally have to name a representative in the United Kingdom, unless you are a public body or your processing is rare and low risk.High confidence
- Can the data leave the country?
- Yes, with paperwork. The United Kingdom has no general law forcing data to stay in the country. Send it to the European Economic Area or another approved country and you need nothing extra; send it anywhere else and you need an approved contract plus a written risk assessment. Three industries are stricter: telecoms, the health service and classified government work. Banking, payments, insurance, securities, education, online gambling and mapping have no location rule that we could find.High confidence
- What do I have to do to send it abroad?
- The model is an approved-list one. If the destination is on the government's approved list you may send data with no extra paperwork. If it is not, you must sign the government's own contract template and run a risk assessment first. The list is well populated: the whole European Economic Area plus Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, South Korea, Switzerland and Uruguay, with partial cover for Canada, Japan and the United States.High confidence
- Who enforces this — and are they actually working?
- The Information Commissioner's Office, and it is very much working. It fined Capita fourteen million pounds (about $18 million) in October 2025, Reddit £14.47 million (about $18.5 million) in February 2026, and the owner of Imgur in the same month, and it issues smaller marketing fines almost monthly. Watch a quirk: a replacement body called the Information Commission legally exists but had no staff and did no work in its first financial year, so the old office is still the one that acts.High confidence
- How long must I keep it, and when must I delete it?
- There is no single deletion deadline. The rule is that you keep personal data only as long as you actually need it, and you must be able to explain the period you chose. Pulling the other way are minimum keeping periods: company and tax records for six years, telecoms connection records for up to twelve months if the government serves a notice, and telecoms security data for thirteen months. Where a minimum and a maximum clash, the legal duty to keep wins and you keep the data.High confidence
- What happens when something goes wrong?
- Count at least three clocks. Any organisation has 72 hours to tell the privacy regulator about a personal data breach, and must tell the affected people if the risk to them is high. Telecoms and internet providers also have 72 hours under the electronic communications rules — that used to be 24 hours and quietly changed on 20 August 2025. Operators of essential services such as water, energy and transport have their own 72-hour clock to their own regulator.High confidence
- What's the trap?
- Five. (1) A child can consent at 13 here, not 16 — but the children's design code covers everyone under 18, and the regulator fined Reddit £14.47 million (about $18.5 million) for weak age checks. (2) Telecoms firms must keep some backup data physically in Britain. (3) Health service data can only go to approved countries, so the standard contract does not help you. (4) Misusing personal data can be a crime, not just a fine. (5) The government can secretly order a company to weaken its security, and Apple is fighting one of those orders right now.Medium confidence
- What's about to change?
- Two things to watch in the next twelve months. A cyber security bill is going through Parliament and will widen incident reporting to data centres and managed service suppliers — it is not law yet, so do not plan as if it were. And the privacy regulator is due to be replaced by a new body called the Information Commission, but only once ministers lay the paperwork, which had not happened by mid-2026. The regulator is also writing a statutory code on artificial intelligence.High confidence
- Hardest industry wall
- Telecoms — The Electronic Communications (Security Measures) Regulations 2022, with the Telecommunications Security Code of Practice 2026 (version 1.1)